CVE-2025-55182

Meta React Server Components: Remote Code Execution

As of , CVE-2025-55182 in Meta React Server Components is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch now.

Exploited
Yes: CISA listed it on 5 December 2025
US federal deadline
12 December 20257 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 12 December 2025.
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module and 1 Exploit-DB entry
Fix
Vendor advice: github.com and react.devLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

CISA's description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

The CVE record's description, from Meta

CVE published
3 December 2025
Assigned by
Meta
CVSS
10.0 Critical (CVSS 3.1, from the CNA)
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. CISA changed its entry. Deadline moved from 26 December 2025 to 12 December 2025. Edited: notes.
  4. CISA changed its entry. Edited: notes and description.
  5. CISA changed its entry. Ransomware use: Unknown to Known.
  6. The US federal deadline to fix it.
  7. Exploit-DB published an exploit (EDB-ID 52506).

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further